Impact
The vulnerability arises in WordPress Bookify plugin (myCred:Bookify) versions 1.1.1 or earlier, where the plugin fails to enforce proper access controls on certain subscriber‑only REST endpoints. As a result, a user with limited permissions can potentially access, modify, or delete data that should be restricted. This can lead to unauthorized data exposure or tampering, classified under CWE‑862. The primary impact is privilege escalation within the WordPress installation, potentially compromising the integrity and confidentiality of booking data.
Affected Systems
This flaw affects WordPress sites that have the myCred Bookify plugin installed at version 1.1.1 or earlier. Any site using these versions of the plugin is susceptible. No other plugins or WordPress core versions are mentioned.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests that the probability of a publicly available exploit is extremely low at present. The vulnerability is not listed in CISA KEV. The attack vector is likely web‑based against the plugin’s API endpoints; a user authenticated as a subscriber may trigger the misuse, though the exact prerequisites are not detailed in the CVE and therefore inferred from the description.
OpenCVE Enrichment